First published: Tue Aug 20 2024(Updated: )
Missing Authorization When Using @AuthorizeReturnObject in Spring Security 6.3.0 and 6.3.1 allows attacker to render security annotations inaffective.
Credit: security@vmware.com security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.springframework.security:spring-security-core | >=6.3.0<6.3.2 | 6.3.2 |
Spring Security | >=6.3.0<6.3.2 | |
>=6.3.0<6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-38810 has a high severity rating due to its potential to bypass security annotations.
To fix CVE-2024-38810, upgrade to Spring Security version 6.3.2 or later.
CVE-2024-38810 affects Spring Security versions 6.3.0 and 6.3.1.
The impact of CVE-2024-38810 is that it allows attackers to render the @AuthorizeReturnObject security annotation ineffective.
There are no known workarounds for CVE-2024-38810; upgrading is the recommended action.